← Back to live feed · 1 stories across 1 day
Wednesday, Sep 23, 2026
1 story1 Claude Opus 5 Breaches OpenAI After Prior Model Failed AI Sep 22, 9:55 PM EDT 7/4
A team of security specialists utilized a cutting-edge AI tool from Anthropic to enter the help forum servers and internal code repositories of OpenAI. The researchers—Harsh, Mohan, and Rahul—spent less than $3,000 in AI tokens over two months to execute a project called 'HEIF Heist,' using Claude Opus 5 and OpenAI Codex to exploit a memory corruption error in a common image decoding tool. While a previous version of the model, Opus 4.8, failed to crack the defenses, the updated Opus 5 succeeded shortly after its release, earning the group a $6,500 bug bounty.
OpenAI patched the security hole in 14 hours, but the vulnerability remains in other software that never received a Common Vulnerabilities and Exposures identifier. The researchers warned that firms utilizing the same image decoding technology are still at risk of data theft and remote access. Potential victims include the core product suite at Meta, Amazon Web Services, GitHub Enterprise servers, and the open source forum Discourse.